Impact
Dolibarr versions prior to 24.0.0 contain a broken object‑level authorization flaw in the REST API bank account write routes. An authenticated attacker who has third‑party creation rights can create, replace, or delete bank account records for any company without needing read access to that company. By injecting attacker‑controlled IBANs as creditor accounts, the attacker can cause regenerated SEPA credit‑transfer files to point to their own accounts, thereby redirecting outgoing payments.
Affected Systems
The affected system is Dolibarr. Versions before 24.0.0 are vulnerable. Any deployment that exposes the REST API for company bank accounts to authenticated users with third‑party creation rights is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The exploitation requires legitimate authentication with appropriate third‑party rights; no additional privileges are needed. Based on the description, it is inferred that financial loss and breach of integrity are possible if redirected payments are processed. Because the vulnerability is not currently listed in the CISA KEV catalog and no EPSS score is available, its current exploitation probability is uncertain, but the potential for significant monetary impact is high. Remediation is strongly recommended for organizations running vulnerable versions.
OpenCVE Enrichment